Live data from Hacker News

What It's Like When the FBI Asks You to Backdoor Your Software

securitywatch.pcmag.com

11–20 of 37 posts

Re: What It's Like When the FBI Asks You to Backdoor Your Software

#11
post #9

Earlier quoted context omitted.

So is unauthorized access to a protected computer, yet a lot of that goes on at security conferences too.

I guess, according to your logic, anything goes then at these conferences?

I'm sorry, if I may ask, what is the use of the answer to your question?

Re: What It's Like When the FBI Asks You to Backdoor Your Software

#12
post #9

Earlier quoted context omitted.

So is unauthorized access to a protected computer, yet a lot of that goes on at security conferences too.

I guess, according to your logic, anything goes then at these conferences?

Many of the people at those conferences aren't afraid to 'color outside the lines,' and impersonating an FBI agent could fall under the umbrella of social engineering, which is another hot topic at security conferences.

I would not view it as outside the realm of possibility.

Re: What It's Like When the FBI Asks You to Backdoor Your Software

#13
Sounds more like a marketing sham than a real FBI encounter to me.

Really? The FBI agent approached her and started talking to her before she had even removed her mic? And everybody (including the agent) heard?

Let me guess, she vehemently denied the offer? (I'll admit I didn't even bother to read past the second paragraph of this "article".)

I don't think so...

Re: What It's Like When the FBI Asks You to Backdoor Your Software

#14

What a missed opportunity. The proper response would have been to "take it under contemplation", get his name & ID, and get as much documentation of the request as possible (enough to verify, does this guy actually work for the FBI, or is it some random "jokester" of the kind that hangs out at security conferences). As it stands, it's basically one level up from an urban myth. Some guy asked her to do something shady…

> Her lecture concluded, she proceeded to grill the agent. "I asked if he had official paperwork for me, if this was an official request, who his boss was," said Sell. "He backed down very quickly."

Re: What It's Like When the FBI Asks You to Backdoor Your Software

#15

Sounds like a publicity stunt or a hoax.

It doesn't sound like that to anyone who has worked in security. This is their routine MO.

Right, that explains why we hear about this exact scenario playing out all the time... oh wait.

Re: What It's Like When the FBI Asks You to Backdoor Your Software

#16
post #14

What a missed opportunity. The proper response would have been to "take it under contemplation", get his name & ID, and get as much documentation of the request as possible (enough to verify, does this guy actually work for the FBI, or is it some random "jokester" of the kind that hangs out at security conferences). As it stands, it's basically one level up from an urban myth. Some guy asked her to do something shady…

> Her lecture concluded, she proceeded to grill the agent. "I asked if he had official paperwork for me, if this was an official request, who his boss was," said Sell. "He backed down very quickly."

"Backed down" in this context seems to mean "went away politely without answering any questions". Leading with verification and diatribing afterwards leaves you with some documentation, or a strong implication that they're a troll. She just went in the wrong order, which is honestly understandable but leaves us with an unverifiable story.

Re: What It's Like When the FBI Asks You to Backdoor Your Software

#17

Sounds more like a marketing sham than a real FBI encounter to me. Really? The FBI agent approached her and started talking to her before she had even removed her mic? And everybody (including the agent) heard? Let me guess, she vehemently denied the offer? (I'll admit I didn't even bother to read past the second paragraph of this "article".) I don't think so...

[deleted]

Re: What It's Like When the FBI Asks You to Backdoor Your Software

#18
'in addition to employing who Sell calls the "best crypto people," Sell said that individual messages are bound to their intended device. "Even in 20 years or 100 years, if the NSA miraculously breaks these [encryption] equations, they still wouldn't be able to read these messages."' uhh, right. And of course this awesome uncrackable crypto relies on private keys stored on teenagers iphones.

Re: What It's Like When the FBI Asks You to Backdoor Your Software

#19
post #2

Or possibly that agent wasn't really an FBI agent but rather was somebody who wanted to test them.

Bit of a risk, considering that impersonating a federal employee is a felony.

Impersonating a federal employee, as itself, is not a felony. Otherwise David Duchovny should have been arrested for impersonating an FBI agent in The X-Files and John Ratzenberger for impersonating a postal service employee in Cheers.

The law is in 18 U.S. Code sec. 912: Officer or employee of the United States:

> Whoever falsely assumes or pretends to be an officer or employee acting under the authority of the United States or any department, agency or officer thereof, and acts as such, or in such pretended character demands or obtains any money, paper, document, or thing of value, shall be fined under this title or imprisoned not more than three years, or both.

That is, 1) impersonating a federal employee, and 2) using that impersonation to get or demand something of value.

This account does not have the person actually getting information, nor demanding access, so does not appear to be felonious.

For example, suppose it was private citizen X impersonating an FBI agent to test Sell's resolve. The query was "if she'd be willing to install a backdoor into Wickr that would allow the FBI to retrieve information", not if citizen X (impersonating an FBI agent) can get that information.

That doesn't seem to be illegal according to the impersonation law.

Post reply on HN